Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/cma: Fix hang when cma_netevent_callback fails to queue_work The cited commit fixed a crash when cma_netevent_callback was called for a cma_id while work on that id from a previous call had not yet started. The work item was re-initialized in the second call, which corrupted the work item currently in the work queue. However, it left a problem when queue_work fails (because the item is still pending in the work queue from a previous call). In this case, cma_id_put (which is called in the work handler) is therefore not called. This results in a userspace process hang (zombie process). Fix this by calling cma_id_put() if queue_work fails.
Product status
51003b2c872c63d28bcf5fbcc52cf7b05615f7b7 (git) before 1ac40736c8c4255d8417b937c9715b193f4a87b3
c2b169fc7a12665d8a675c1ff14bca1b9c63fb9a (git) before ac7897c0124066b9705ffca252a3662d54fc0c9b
d23fd7a539ac078df119707110686a5b226ee3bb (git) before 02e45168e0fd6fdc6f8f7c42c4b500857aa5efb0
45f5dcdd049719fb999393b30679605f16ebce14 (git) before 8b05aa3692e45b8249379dc52b14acc6a104d2e5
45f5dcdd049719fb999393b30679605f16ebce14 (git) before 92a251c3df8ea1991cd9fe00f1ab0cfce18d7711
b172a4a0de254f1fcce7591833a9a63547c2f447 (git)
6.15
Any version before 6.15
6.1.142 (semver)
6.6.94 (semver)
6.12.34 (semver)
6.15.3 (semver)
6.16 (original_commit_for_fix)
References
lists.debian.org/debian-lts-announce/2025/10/msg00008.html
git.kernel.org/...c/1ac40736c8c4255d8417b937c9715b193f4a87b3
git.kernel.org/...c/ac7897c0124066b9705ffca252a3662d54fc0c9b
git.kernel.org/...c/02e45168e0fd6fdc6f8f7c42c4b500857aa5efb0
git.kernel.org/...c/8b05aa3692e45b8249379dc52b14acc6a104d2e5
git.kernel.org/...c/92a251c3df8ea1991cd9fe00f1ab0cfce18d7711